Impact
The driver for the ltrf216a light sensor in the Linux kernel leaks a runtime power management reference when read operations fail. The leaked reference prevents the kernel from decrementing the PM usage count, blocking the device from autosuspending. This results in the sensor staying powered unnecessarily, potentially draining battery or wasting system power and effectively denying the intended power‑management service.
Affected Systems
The vulnerability exists in the Linux kernel, affecting any build that includes the ltrf216a light sensor driver. No specific kernel version boundaries are provided, so all kernel versions that ship the driver until the patch are potentially impacted.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a low probability of real‑world exploitation, and the issue is not listed in the CISA KEV catalog. The CVSS score is not supplied. Attackers would need to induce a read failure in the ltrf216a driver—likely requiring local or privileged access—to trigger the reference leak. Even if exploited, the impact is limited to loss of autosuspend functionality, passing the risk level to device‑level denial of service rather than system‑wide compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA